DrochaidHorizon3.ai
NodeZero/Australia & NZ compliance/Essential Eight
Australia & NZ compliance

ASD Essential Eight Maturity Level 2

The Australian Signals Directorate's prioritised mitigation strategies for protecting organisations against cyber security incidents. Maturity Level 2 targets adversaries willing to invest more time in a target and in the effectiveness of their tools.

See where NodeZero applies

What is the Essential Eight?

The Essential Eight is the Australian Signals Directorate's prioritised set of mitigation strategies designed to protect organisations against cyber security incidents. Rather than attempting to address every possible threat, the ASD identified eight strategies that, when implemented together, make it significantly harder for adversaries to compromise systems. The framework defines four maturity levels, from a baseline Maturity Level Zero to Maturity Level Three, each targeting increasing levels of adversary tradecraft.

Organisations come to the Essential Eight from very different starting points — some standing the controls up for the first time, often with grant funding behind a formal Maturity Action Plan, others lifting an established programme toward Level 2 or 3. At Maturity Level 2 -- targeted at adversaries willing to invest more time in a target and in the effectiveness of their tools -- application control blocks unauthorised executables, patches are applied within defined timeframes, MFA resists phishing attempts, and administrative privileges are tightly restricted. The gap between having a control and proving it works under pressure is exactly where most organisations struggle during assessment.

ASD Essential Eight Maturity Model

Where NodeZero applies

NodeZero provides direct technical evidence across all eight Essential Eight strategies. Coverage is strongest on the strategies that govern privilege, credentials, and exploitable weakness (#1 Application control, #2 Patch applications, #3 Patch OS, #5 User application hardening, #6 Restrict admin privileges, #7 MFA) — where we prove the attack techniques each control is designed to prevent actually fail when they should. For #4 Macro settings and #8 Regular backups, we contribute attack-impact evidence (phishing blast radius, backup-infra access, honeytoken alerts) rather than policy-state evidence, and we clearly flag what still needs separate documentation.

Essential Eight Maturity Model — Nov 2023

This mapping reflects our best-effort analysis of where NodeZero's autonomous pentesting produces relevant technical evidence against each requirement. It is intended to help you focus security effort on the controls NodeZero can test — not to serve as a compliance certification. You remain responsible for your own compliance assessment, for validating applicability to your environment, and for evidencing the requirements NodeZero does not directly test.

Showing coverage grouped by compliance category.

Patch applications

Identifies unpatched applications and exploits known vulnerabilities.

Internal pentesting·ML1, ML2, ML3Core

Discovers every reachable application and fingerprints versions across the estate — including bespoke, line-of-business and unsupported releases — and exploits known CVEs as part of attack chains, surfacing where patching has slipped against the ML1 and ML2 windows.

External pentesting·ML1Core

Continuously discovers internet-facing services and exploits unpatched vulnerabilities the way a ransomware actor would, surfacing on every scheduled run where internet-facing online services remain exploitable past the 48-hour critical and two-week non-critical patching windows — evidence that patching has slipped, not proof the cadence was met.

Rapid Response·ML1, ML3Pro & Elite

Horizon3.ai's attack team publishes targeted tests for newly disclosed critical CVEs — often within hours of disclosure, and in some cases ahead of the public patch — so exposure to the 48-hour window at ML1 (online services) and ML3 (productivity software) is auditable in the window between a CVE going public and your next scan. The catalogue extends beyond network appliances to Microsoft and Linux-hosted software — SharePoint and CyberPanel among the published examples.

Vulnerability Risk Intelligence·ML1, ML2, ML3Elite only

Ingests existing scanner exports across every application class and ranks CVE-asset pairs by exploitability — so triage inside the ML2 one-month and ML3 two-week windows is governed by real attack reach rather than CVSS alone.

14 controls mapped·ML1–ML3

Patch operating systems

Identifies unpatched operating systems and exploits known vulnerabilities.

Internal pentesting·ML1, ML3Core

Discovers every reachable host, fingerprints OS version and build, and exploits missing patches as part of lateral-movement chains — direct evidence of unpatched workstations, internal servers and unsupported OS releases that should have been replaced.

External pentesting·ML1Core

Discovers and exploits unpatched internet-facing servers and network devices, providing attack-side evidence on every scheduled run of where perimeter OS patching remains exploitable past the 48-hour critical and two-week non-critical windows — evidence patching has slipped, not proof the cadence was met.

Rapid Response·ML1, ML3Pro & Elite

Targeted tests for newly disclosed critical OS CVEs — both at the perimeter (ML1 internet-facing) and inside the network (ML3 workstations and non-internet servers) — let you verify exposure in the window between a CVE going public and your next scan. The catalogue includes Microsoft server components — a WSUS misconfiguration test card among recent additions — alongside the appliance CVEs it is best known for.

Vulnerability Risk Intelligence·ML1, ML3Elite only

Re-ranks workstation and non-internet OS CVE-asset pairs by exploitability, classifying them as Confirmed Exploitable, Contextually Exploitable or Threat Actor Pressure — attacker-first prioritisation inside the ML1 one-month and ML3 one-month windows.

11 controls mapped·ML1, ML3

Multi-factor authentication

Tests MFA enforcement and bypass resistance.

Internal pentesting·ML1, ML2, ML3Core

Discovers and tests every authentication endpoint reached during an internal pentest, surfacing privileged and unprivileged accounts not actually protected by MFA, and reaching databases, file shares and source-code repositories where MFA on data-repository access (ML3) hasn't been enforced.

External pentesting·ML1Core

Supports credential injection — inject a compromised credential into an external pentest and NodeZero runs the test from an authenticated perspective, proving the real impact of a stolen credential from outside — attack-impact evidence toward the MFA obligations, not a live test of the deployed factor itself.

Phishing Impact Testing·ML1, ML2, ML3Core

Takes the credentials your phishing tool captures and demonstrates what an attacker actually reaches across internal, third-party and customer services — attack-impact evidence of where MFA is absent or fails to contain a phished credential. It does not run a live relay against the factor, so it does not on its own prove SMS, push or FIDO2 meets the phishing-resistant qualifier ML2 introduces and ML3 strengthens.

Web application pentesting·ML1Priced separately

NodeZero's WebApp Pentesting tests reachable customer-facing and third-party authentication surfaces for exploitable weaknesses where they form real attack paths that defeat the factor protecting sensitive customer data.

AD Password Audit·ML1Core

Surfaces the weak, breached and reused passwords MFA is expected to compensate for — direct evidence of the failure mode if the factor itself is bypassed.

Cloud pentesting·ML2Core

Attacks the Entra identity plane — including Seamless SSO Silver Ticket and Entra Connect credential dumping — proving whether MFA on privileged users actually resists documented bypass techniques.

Insider Threat Testing·ML2, ML3Core

Starts from a real authenticated user's credentials and proves what that user can actually reach — attack-impact evidence of where a single credential is all that stands between a user and the systems and data repositories MFA is meant to gate.

NodeZero TripwiresPro & Elite

Autonomous decoy AD accounts baited for Kerberoasting and AS-REP roasting, paired with DC Kerberos logging and real-time SIEM/SOAR alerting — validates whether a live credential-theft attempt against the identity plane is actually detected, the detection half of the ML2/ML3 logging-and-analysis obligation below. Central log collection, log protection and incident-response enactment remain outside autonomous testing.

15 controls mapped·ML1–ML3

Restrict administrative privileges

One of NodeZero's strongest areas — tests privilege boundaries, credential strength, and access separation.

Internal pentesting·ML1, ML2, ML3Core

Proves end-to-end attack paths from unprivileged access to domain compromise, and attempts LSASS dumping and NTLM-hash extraction from host memory — successful extraction is direct evidence of separation, LSA Protection, Credential Guard or Remote Credential Guard failures across ML1 and ML3. Kerberoasting and AS-REP roasting are separate identity attacks against the KDC, not evidence about Credential Guard's state.

Phishing Impact Testing·ML1Core

Simulated phishing compromise of a privileged account proves whether the ML1 internet/email isolation control actually prevents that account being abused after credential theft.

BloodHound (integrated)·ML1Core

AD attack-graph visualisation makes the cross-tier logon paths that break the ML1 unprivileged/privileged separation control visible and fixable.

Insider Threat Testing·ML1, ML3Core

Starts from a real privileged or unprivileged user perspective and proves what they can actually reach — empirical evidence of the ML1 separation rule and the ML3 least-privilege limitation on systems, applications and data repositories.

AD Password Audit·ML2Core

First AI to solve GOAD in 14 minutes (Horizon3-reported); it is not uncommon for NodeZero to crack more than 50% of the passwords it tests on a first audit. Audits break-glass, local-administrator and service-account credentials against the ML2 long, unique and managed requirement, and surfaces weak or never-rotated privileged accounts worth reviewing against the ML2 12-month revalidation and 45-day inactivity thresholds — the lifecycle disable decision itself remains an identity-governance check.

Cloud pentesting·ML2Core

Hybrid and cloud environments routinely break the ML2 rule that privileged operating environments not be virtualised within unprivileged ones; cloud pentesting tests privilege-escalation paths between on-prem and AWS, Azure or Kubernetes.

High-Value Targeting·ML3Elite only

Autonomously infers crown-jewel systems and identities — executive accounts, production and virtualisation infrastructure — and proves the attack paths that reach them: additive attack-impact evidence for the ML3 least-privilege rule, on top of what Insider Threat Testing already demonstrates, that an over-provisioned account's reach actually extends to crown jewels.

External pentesting·ML3Core

Supports credential injection — inject a compromised credential into an external pentest and NodeZero proves from outside what that account actually reaches across the internet-facing estate, attack-impact evidence of whether a stolen privileged credential is contained.

NodeZero TripwiresPro & Elite

Autonomous decoy AD accounts baited for Kerberoasting and AS-REP roasting, paired with DC Kerberos logging and real-time SIEM/SOAR alerting — validates whether a live identity attack against a privileged account actually surfaces to the SOC, the detection half of the ML2/ML3 logging-and-analysis obligation below. Central log collection, log protection and incident-response enactment remain outside autonomous testing.

12 controls mapped·ML1–ML3

Application control

Tests application control bypass, blocklist effectiveness, and EDR enforcement.

Endpoint Security Effectiveness·ML1, ML3Core

Per-host block/allow telemetry across 40+ EDR vendors surfaces workstations (ML1) and non-internet servers (ML3) where successful payload execution proves neither EDR nor application-control policy intervened — the exact gap each tier of application-control implementation is meant to close.

Internal pentesting·ML1, ML2, ML3Core

Drops and executes payloads from %TEMP%, %APPDATA%, browser cache, system directories and ProgramData paths during attack chains, attempts BYOVD (Bring Your Own Vulnerable Driver) and known LOLBins — successful execution is direct evidence the ML1, ML2 and ML3 application-control rulesets aren't enforcing.

External pentesting·ML2Core

Attempts execution against internet-facing servers from the attacker perspective — proves whether the ML2 application-control implementation is actually present and enforcing on the servers attackers touch first.

NodeZero TripwiresPro & Elite

Autonomous decoy AD accounts baited for Kerberoasting and AS-REP roasting, paired with DC Kerberos logging and real-time SIEM/SOAR alerting — validates whether a live identity attack is actually detected, the detection half of the ML2/ML3 logging-and-analysis obligation below. Central log collection, log protection and incident-response enactment remain outside autonomous testing.

9 controls mapped·ML1–ML3

Restrict Microsoft Office macros

Tests whether macro-based attack paths are viable in practice.

Phishing Impact Testing·ML1, ML2, ML3Core

Takes the credentials your phishing tool captures and proves their blast radius inside the network — attack-impact evidence of the consequence the macro-restriction rules are meant to prevent. NodeZero does not deliver or detonate a macro, so whether the macro-execution restrictions enforce (internet-origin blocking, Win32-API blocking, trusted-source/sandbox restriction) sits alongside the other macro-policy items in the gap, not as direct evidence.

3 controls mapped·ML1–ML3

User application hardening

Tests attack vectors that application hardening should prevent.

Internal pentesting·ML1, ML2, ML3Core

Fingerprints installed browsers, Java runtimes, .NET versions and PowerShell engines during host enumeration — surfaces the IE 11, browser-Java, .NET 3.5 and PowerShell 2.0 surfaces ML1 and ML3 require to be removed, and chains Office and PDF child-process and PowerShell Constrained Language Mode failures into attack paths.

Endpoint Security Effectiveness·ML2Core

Per-host EDR block/allow telemetry surfaces where generic attacker techniques are or aren't stopped on a host — supporting evidence around the ML2 Office-hardening rules. NodeZero does not detonate Office to trigger these specific ASR rules, so their enforcement is confirmed by configuration review.

Phishing Impact Testing·ML2Core

Proves the blast radius of a phished credential inside the network — attack-impact evidence of the consequence the ML2 OLE-prevention rule is meant to prevent. NodeZero does not deliver or detonate OLE-package lures or .HTA droppers, so the rule's enforcement is a hardening-policy check (see gap).

NodeZero TripwiresPro & Elite

Autonomous decoy AD accounts baited for Kerberoasting and AS-REP roasting, paired with DC Kerberos logging and real-time SIEM/SOAR alerting — validates whether a live identity attack is actually detected, the detection half of the ML2/ML3 logging-and-analysis obligation below. Central log collection, log protection and incident-response enactment remain outside autonomous testing.

10 controls mapped·ML1–ML3

Regular backups

Tests access controls around backup infrastructure — not backup integrity itself.

Internal pentesting·ML1, ML2, ML3Core

Chains lateral-movement attack paths through backup storage from compromised unprivileged and privileged (non-backup-admin) accounts — proves whether the ML1, ML2 and ML3 access, modification and self-access restrictions actually hold against the way ransomware operators reach backups.

NodeZero Tripwires·ML2, ML3Pro & Elite

Places decoy AWS credential files, MySQL dumps and Windows process monitors near backup infrastructure and within retained-backup paths — silent until triggered, then alerts to your SIEM when a non-backup privileged or backup-admin account touches them, surfacing the ML2 and ML3 modification and deletion controls that should have prevented it.

7 controls mapped·ML1–ML3
Essential Eight kit

See every control mapped to NodeZero

The full control-by-control coverage map — every Essential Eightrequirement matched to the NodeZero capability that produces evidence for it, with maturity-level grouping and source citations. We'll email you the link and a downloadable copy.

Who does this apply to?

Under the Protective Security Policy Framework (PSPF), non-corporate Commonwealth entities must implement each of the eight strategies to Maturity Level 2 -- PSPF Release 2026 carries this as a mandatory requirement, with annual reporting. For corporate Commonwealth entities and wholly-owned Commonwealth companies, the PSPF represents better practice.

Beyond government, the Essential Eight is widely adopted by organisations in the defence supply chain (where DISP membership increasingly expects Essential Eight alignment), critical infrastructure operators meeting SOCI Act obligations, government contractors handling sensitive information, and private sector organisations using ASD guidance as their baseline security framework.

If your organisation provides services to the Australian Government, handles government data, operates critical infrastructure, or simply wants to align with Australia's most recognised cyber security standard, the Essential Eight applies to you.

Maturity model

Three levels of the climb

The Essential Eight is assessed across three target maturity levels (above a baseline Maturity Level Zero), each targeted at a progressively more capable adversary. This page maps coverage across all three target levels, anchored on Level 2 — the level non-corporate Commonwealth entities are required to achieve under the Protective Security Policy Framework (PSPF).

Level 1
Commodity tradecraft

Targets adversaries content to leverage commodity tradecraft that is widely available — the kind that can gain access to, and likely control of, systems without much investment. Controls counter untargeted, opportunistic intrusions.

ASD definition
Level 2This page
Targeted tradecraft

Targets adversaries willing to invest more time in a target and in the effectiveness of their tools — well-known evasion techniques, credential abuse, and working exploits rather than off-the-shelf malware alone.

ASD definition
Level 3
Adaptive adversaries

Targets adversaries who are more adaptive and much less reliant on public tools and techniques — able to exploit weaknesses in policy, process, and technology, and willing to invest in bypassing specific defences.

ASD definition
FAQ

Common questions

What is the Essential Eight?

The Essential Eight is the Australian Signals Directorate's baseline of the eight most effective mitigation strategies from its Strategies to Mitigate Cyber Security Incidents — designed to make it much harder for adversaries to compromise systems. It is structured across four maturity levels, from Maturity Level Zero — which signifies weaknesses in an organisation's overall cyber security posture — up to Maturity Level Three, with each level above zero mitigating increasing levels of adversary tradecraft and targeting.

cyber.gov.au — Essential Eight explained
Is the Essential Eight mandatory?

Under the Protective Security Policy Framework, non-corporate Commonwealth entities must implement each of the eight strategies to Maturity Level 2 — PSPF Release 2026 carries this as a mandatory requirement, with annual reporting — while for corporate Commonwealth entities the PSPF represents better practice. Beyond government, DISP membership requires Essential Eight ML2, the SOCI CIRMP Rules accept the Essential Eight as a cyber framework, and many private organisations adopt it as their baseline.

protectivesecurity.gov.au — PSPF annual release
How does NodeZero help with Essential Eight compliance?

NodeZero is a continuous security validation platform that produces direct technical evidence across all eight strategies — running autonomous penetration tests that prove the attack techniques each control is designed to prevent actually fail when they should. It is strongest on the strategies governing privilege, credentials and exploitable weakness: application control, patching of applications and operating systems, user application hardening, restricting administrative privileges and multi-factor authentication.

cyber.gov.au — Essential Eight assessment process guide
Does NodeZero cover all eight Essential Eight strategies?

Yes — NodeZero provides direct technical evidence across all eight strategies, but the evidence type differs. For restricting Microsoft Office macros and regular backups it contributes attack-impact evidence — phishing blast radius, backup-infrastructure access and honeytoken alerts — rather than policy-state evidence. It does not replace a formal Essential Eight maturity assessment; it gives you attack-based evidence to put in front of the assessor.

cyber.gov.au — Essential Eight maturity model
What changed in the November 2023 Essential Eight update?

In November 2023 the ASD made substantial updates to the Essential Eight Maturity Model — rebalancing patching timeframes, phishing-resistant multi-factor authentication, cloud-service management, and internet-facing detection and response. Organisations assessed under the previous model may no longer meet current requirements. NodeZero tests against current control expectations, so a pentest shows where controls fall short of the updated Level 2 requirements before your next assessment.

cyber.gov.au — Essential Eight maturity model changes
What is the difference between Maturity Level 1 and Maturity Level 2?

Maturity Level 1 counters commodity tradecraft — untargeted, opportunistic intrusions using widely available tools. Maturity Level 2 targets adversaries willing to invest more time in a target and in the effectiveness of their tools, employing well-known tradecraft to bypass controls and evade detection, including techniques to circumvent weak multi-factor authentication. Level 2 also adds requirements such as centralised event log collection, and it is the level non-corporate Commonwealth entities must achieve under the PSPF.

cyber.gov.au — Essential Eight maturity model
Trusted by 7,013 organisations worldwide
Powers the NSA's CAPT program310,332 pentests4.7 Gartner

Close the gaps before your next assessment

See how NodeZero generates audit-ready evidence for your compliance obligations. We'll walk you through where NodeZero applies for your specific framework.